In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: Fix possible UAF on isoconnfree
This attempt to fix similar issue to scoconnfree where if the conn->sk is not set to NULL may lead to UAF on isoconnfree.
[
{
"id": "CVE-2025-40141-15c205e2",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"109427871610741948230435546006187475567",
"26548651462460474418918021803479809903",
"271082052237541772899516521680244228967"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@80689777919f02328eb873769de4647c9dd3e371",
"target": {
"file": "net/bluetooth/iso.c"
}
},
{
"id": "CVE-2025-40141-3ec73e32",
"signature_version": "v1",
"digest": {
"length": 301.0,
"function_hash": "5902465819434186301868799915691316138"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eba6d787ec117a5d2c60f9644e0a39c18542b6be",
"target": {
"file": "net/bluetooth/iso.c",
"function": "iso_sock_kill"
}
},
{
"id": "CVE-2025-40141-567451ad",
"signature_version": "v1",
"digest": {
"length": 301.0,
"function_hash": "5902465819434186301868799915691316138"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c92ad1a155ccfa38b87bd1d998287e1c0a24248d",
"target": {
"file": "net/bluetooth/iso.c",
"function": "iso_sock_kill"
}
},
{
"id": "CVE-2025-40141-6e03086f",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"109427871610741948230435546006187475567",
"26548651462460474418918021803479809903",
"271082052237541772899516521680244228967"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9950f095d6c875dbe0c9ebfcf972ec88fdf26fc8",
"target": {
"file": "net/bluetooth/iso.c"
}
},
{
"id": "CVE-2025-40141-7c7ea628",
"signature_version": "v1",
"digest": {
"length": 301.0,
"function_hash": "5902465819434186301868799915691316138"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@80689777919f02328eb873769de4647c9dd3e371",
"target": {
"file": "net/bluetooth/iso.c",
"function": "iso_sock_kill"
}
},
{
"id": "CVE-2025-40141-a08a2fd3",
"signature_version": "v1",
"digest": {
"length": 301.0,
"function_hash": "5902465819434186301868799915691316138"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9950f095d6c875dbe0c9ebfcf972ec88fdf26fc8",
"target": {
"file": "net/bluetooth/iso.c",
"function": "iso_sock_kill"
}
},
{
"id": "CVE-2025-40141-b5f7f77c",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"109427871610741948230435546006187475567",
"26548651462460474418918021803479809903",
"271082052237541772899516521680244228967"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eba6d787ec117a5d2c60f9644e0a39c18542b6be",
"target": {
"file": "net/bluetooth/iso.c"
}
},
{
"id": "CVE-2025-40141-f3b112c5",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"109427871610741948230435546006187475567",
"26548651462460474418918021803479809903",
"271082052237541772899516521680244228967"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5319145a07d8bf5b0782b25cb3115825689d42bb",
"target": {
"file": "net/bluetooth/iso.c"
}
},
{
"id": "CVE-2025-40141-f9265450",
"signature_version": "v1",
"digest": {
"length": 301.0,
"function_hash": "5902465819434186301868799915691316138"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5319145a07d8bf5b0782b25cb3115825689d42bb",
"target": {
"file": "net/bluetooth/iso.c",
"function": "iso_sock_kill"
}
},
{
"id": "CVE-2025-40141-fcb29efd",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"109427871610741948230435546006187475567",
"26548651462460474418918021803479809903",
"271082052237541772899516521680244228967"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c92ad1a155ccfa38b87bd1d998287e1c0a24248d",
"target": {
"file": "net/bluetooth/iso.c"
}
}
]